logo

Im In Your Leenucks Box Changing Your Password

ID: 96d09343-0d1e-5d45-a640-e7a90f80b48d

STIX ID: report--96d09343-0d1e-5d45-a640-e7a90f80b48d

Feed Name: Darknet

Threat Score
75/100

Date Published: 2007-09-18

Date Updated: 2026-05-12

...
...

**Executive Summary:** DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major browsers (Chrome/Edge/Brave via an App-Bound Encryption bypass using headless Chromium + IElevator COM and DLL injection; Opera/Opera GX/Vivaldi via DPAPI; Firefox via NSS decryption), includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and is distributed as a compiled Windows executable intended for red-team assumed-breach scenarios but represents a high-risk capability if used maliciously.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.